PTC Windchill & FlexPLM Unauthenticated RCE – CVE-2026-12569

TL;DR: A critical flaw in PTC’s Windchill PDMLink and FlexPLM lets an unauthenticated attacker run arbitrary code on the server by sending a single booby-trapped request. It is being exploited in the wild to plant JSP web shells, it is on CISA’s KEV list, and patches are out now — update without delay.

Key takeaways

  • CVE-2026-12569 is a CVSS 9.3 (Critical) unauthenticated remote code execution bug caused by insecure deserialisation of untrusted data in PTC Windchill PDMLink and FlexPLM.
  • It is actively exploited. Attackers are dropping persistent JSP web shells under /Windchill/login/ and using them for command execution and data theft.
  • CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 25 June 2026, with a federal remediation deadline of 28 June 2026 — the first PTC product ever to make the list.
  • Patches are available. Upgrade to the fixed releases listed in PTC advisory CS473270, then hunt for the published indicators of compromise.

CRITICAL Windchill / FlexPLM RCE CVE-2026-12569
CVSS Score9.3  (CVSS v4.0, PTC/CNA)
CVSS VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Vulnerability TypeDeserialisation of untrusted data → RCE  (CWE-502, CWE-20)
Affected ProductsPTC Windchill PDMLink & FlexPLM — all releases up to and including 11.0 M030, plus 11.1 M020, 11.2.1.0, 12.0.x, 12.1.x, 13.0.x and 13.1.x (and all CPS versions). See PTC CS473270 for the full matrix.
Attack VectorNetwork — no authentication, no user interaction required.
Actively ExploitedYes — in the wild  (CISA KEV, added 25 Jun 2026; JSP web shells observed)
Patch AvailableYes — fixed releases published by PTC (advisory CS473270).
Disclosure Date17 June 2026 (CVE published; PTC advisory issued)

What is CVE-2026-12569?

CVE-2026-12569 is a critical remote code execution vulnerability in two of PTC’s flagship enterprise platforms: Windchill PDMLink, a product data management (PDM) system, and FlexPLM, a product lifecycle management (PLM) suite used heavily in manufacturing, retail and consumer-goods design. These systems sit at the heart of engineering and product organisations — they hold CAD files, bills of materials, specifications and supplier data — which makes them a high-value target.

The flaw is an insecure deserialisation issue (CWE-502, with CWE-20 improper input validation also assigned). In plain terms, the application accepts a serialised data object from the network and rebuilds it into a live object without first checking that it is safe. A crafted object can be made to trigger code execution during that rebuild. Because the vulnerable path requires no authentication and no user interaction, any attacker who can reach the Windchill or FlexPLM web interface can attempt it.

PTC, acting as the CNA, scored it 9.3 Critical on CVSS v4.0. NVD enrichment was still pending at the time of writing, so the 9.3 figure is PTC’s authoritative score; some early third-party coverage cited a 10.0 figure, which we have not been able to confirm against a primary source.

How the Windchill / FlexPLM exploit works

At a high level, the attack is simple to describe: the attacker sends one malicious HTTP request to an internet-reachable Windchill or FlexPLM endpoint, the server deserialises attacker-controlled data, and that triggers code execution. From there, the attacker writes a web shell to disk and gains a durable foothold.

In more depth, the root cause is the classic Java deserialisation problem. The application reads a serialised object from request data and calls a deserialisation routine on it. If the classpath contains “gadget” classes whose construction has useful side effects, an attacker can chain those side effects into arbitrary command execution — all before any authentication or business-logic check runs. CISA’s own triage of the bug rated its technical impact as total and flagged it as automatable, meaning it is well suited to mass, scripted exploitation.

In the observed in-the-wild attacks, successful exploitation is followed by the attacker dropping a JSP web shell into the web root, using a randomised filename pattern under the login path: /Windchill/login/[0-9a-f]{16}.jsp. The web shell then gives the attacker an interactive command channel for follow-on activity — reconnaissance, file listing and data exfiltration. PTC reports the presence of an flst.txt file in /tmp or the Windchill working directory as a tell-tale sign of attacker file-listing activity.

The following is a non-operational, illustrative sketch of the attack shape — not a working exploit. It shows the pattern defenders should look for in their logs, with no payload details.

# Illustrative only — NOT a working exploit.
POST /Windchill/login/<random-16-hex>.jsp HTTP/1.1
Host: windchill.example.com
X-windchill-req: <attacker marker header>
Content-Type: application/x-java-serialized-object
[serialised object — redacted]

The pre-conditions are minimal: a network-reachable Windchill PDMLink or FlexPLM instance running an affected version. No credentials, no phishing, no internal access required.

Is CVE-2026-12569 actively exploited?

Yes. This is not theoretical. PTC confirmed on 25 June 2026 that it had “received continued reports of heightened threat activity”, with unknown actors exploiting the flaw to deploy JSP web shells against vulnerable systems. On the same day, CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities (KEV) catalog, setting a remediation deadline of 28 June 2026 for US federal civilian agencies. It is the first PTC product vulnerability ever added to the KEV catalog.

The exploitation window has been short and sharp: patches landed around 17 June, and mass exploitation was being reported within days — a now-familiar pattern of attackers weaponising freshly disclosed enterprise bugs faster than organisations can patch. Germany’s Federal Office for Information Security (BSI) considered the situation serious enough to issue an out-of-hours warning to administrators.

How to fix CVE-2026-12569: remediation & mitigation

Patch. PTC has released fixed builds for all affected Windchill PDMLink and FlexPLM releases. Apply the update for your version as set out in PTC advisory CS473270 (linked under Sources). Because the affected matrix spans many releases (11.x, 12.x, 13.x and earlier, including all CPS versions), confirm your exact build against the advisory rather than assuming a single target version. Given confirmed in-the-wild exploitation and the 28 June KEV deadline, treat this as an emergency change.

If you cannot patch immediately:

  • Restrict internet exposure of the Windchill/FlexPLM login endpoint wherever operationally possible — put it behind a VPN or IP allow-list.
  • Block the known command-and-control address 5.180.41.35 at the perimeter firewall.
  • Add a WAF / IDS rule to block any request containing the header X-windchill-req:.

After patching (hunt for compromise). Patching a server that has already been web-shelled does not evict the attacker — assume breach until proven otherwise:

  • Search HTTP access logs for POST requests to /Windchill/login/*.jsp.
  • Scan the filesystem for JSP files matching the pattern /Windchill/login/[0-9a-f]{16}.jsp.
  • Hash any suspicious JSP files and compare against 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c.
  • Check for flst.txt in /tmp or the Windchill working directory — its presence confirms attacker file-listing.
  • If you find evidence of compromise, isolate the host, rotate any credentials and secrets reachable from it, terminate active sessions, and run full incident response.

Detection / IOCs (from PTC):

  • C2 address: 5.180.41.35
  • Additional IPs observed: 172.111.38.31, 216.152.148.54, 104.243.35.131, 74.50.76.146
  • Web-shell path pattern: /Windchill/login/[0-9a-f]{16}.jsp
  • Web-shell hash: 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c
  • Attacker marker header: X-windchill-req:
  • File-listing artefact: flst.txt in /tmp or the Windchill working directory

Frequently asked questions

Is Windchill or FlexPLM in the cloud affected?

The vulnerability affects the Windchill PDMLink and FlexPLM software itself across the listed on-premise releases. Whether a managed/hosted deployment is exposed depends on the version running and its network exposure — verify your build and patch status against PTC advisory CS473270 regardless of where it runs.

We patched. Are we safe now?

Patching closes the door, but if your server was reachable before you patched, it may already have been compromised. Active exploitation has been confirmed, so you should hunt for the web-shell and IOC artefacts above before considering the incident closed.

What is the actual severity — 9.3 or 10.0?

PTC, the assigning authority, scored it 9.3 Critical on CVSS v4.0. NVD had not yet published its own enrichment at the time of writing. Some early reporting referenced a 10.0 figure; we treat PTC’s 9.3 as authoritative until NVD confirms otherwise. Either way, it is a maximum-priority Critical.

Why does a PLM/PDM bug matter so much?

Windchill and FlexPLM hold an organisation’s crown-jewel engineering and product data — designs, BOMs, supplier and specification data. An unauthenticated RCE there is both a full server compromise and a potential intellectual-property breach.

Sources & further reading

  • PTC — Customer & Partner Updates: RCE Vulnerability in Windchill and FlexPLM (advisory): ptc.com
  • PTC — Support article CS473270: ptc.com/en/support/article/CS473270
  • NVD — CVE-2026-12569: nvd.nist.gov
  • CISA — Adds Two Known Exploited Vulnerabilities to Catalog (25 Jun 2026): cisa.gov
  • The Hacker News — CISA Adds Exploited PTC Windchill RCE Flaw to KEV: thehackernews.com
  • CSO Online — Hackers exploit critical PTC Windchill PLM software flaw: csoonline.com
  • heise online — PTC Windchill: BSI warns admins of critical vulnerability: heise.de

ZeroDayHub tracks critical vulnerabilities as they break. Subscribe for updates.

Leave a Reply

Trending

Discover more from Zerodayhub

Subscribe now to keep reading and get access to the full archive.

Continue reading